Weaknesses of type CWE-787

5,154 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2024-42986HIGHTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulEPSS 0.6%CVE-2024-42977HIGHTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerabilitEPSS 0.6%CVE-2024-50854HIGHTenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function.EPSS 0.6%CVE-2024-6137HIGHBT: Classic: SDP OOB access in get_att_search_listEPSS 0.5%CVE-2021-3489HIGHLinux kernel eBPF RINGBUF map oversized allocationEPSS 0.5%CVE-2021-34947HIGHNETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-57876HIGHGV-LPC2011/LPC2211 - unauthorized out-of-bounds writing vulnerability (onvif.cgi)EPSS 0.5%CVE-2026-58592HIGHLadybird - Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssembly ESM IntegrationEPSS 0.5%CVE-2026-16706HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-16887HIGHIBM i is Affected By A Denial of Service Vulnerability DST/SST []EPSS 0.5%CVE-2021-47774HIGHKingdia CD Extractor 3.0.2 - Buffer Overflow (SEH)EPSS 0.5%CVE-2026-16982HIGHIBM i is Affected By Multiple Vulnerabilities in Host ServersEPSS 0.5%CVE-2026-18846HIGHIBM i is Affected By Multiple Vulnerabilities in Host ServersEPSS 0.5%CVE-2026-17425HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-18077HIGHIBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer ProtocolEPSS 0.5%CVE-2024-5303HIGHKofax Power PDF PSD File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-5302HIGHKofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-6811HIGHIrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-6812HIGHIrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-28177HIGHMemory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.5%